Security Flaw in OpenAI's ChatGPT Workspace Could Allow Rogue AI Agents
Researchers have discovered a flaw in OpenAI's ChatGPT workspace agents that could allow an attacker-controlled AI agent to be planted inside a company's ChatGPT workspace. The bug, dubbed 'AgentForger' by Zenity Labs, enables the creation, configuration, and scheduling of a malicious workspace agent within a victim's ChatGPT account. This agent could act autonomously, using the employee's identity and access to rummage through corporate data and send messages. The flaw was reported to OpenAI, which fixed the vulnerability by removing the URL parameter that enabled the attack.